6 Commits
Author SHA1 Message Date
Mike Wichers 17c4df796a Add unlisted visibility: served by link, off the index, noindex
Internal papers need a durable link before member login exists. 'unlisted'
serves a document at its slug but keeps it off /documents and sends
X-Robots-Tag: noindex so it stays out of search results.

Serving and listing are now separate questions: visible() decides whether a
document can be served at all and stays the seam login attaches to, listed()
decides whether it shows on the index. 'members' remains hidden AND
unservable, so the weaker state cannot be mistaken for the gate.

This is obscurity, not access control, and both the README and the manifest
say so. An unlisted link is forwardable.
2026-08-30 09:21:26 -04:00
Mike Wichers 1ecdb32139 Add a document shelf at /documents, served through the app
Files live outside the repo at /srv/scout-website-assets/docs (bind-mounted
read-only at /docs), the same arrangement as the photos, published by a
manifest.json beside them. Adding a document is a file drop plus a manifest
entry - the app re-reads the manifest on mtime change, so no rebuild and no
redeploy.

The manifest maps a stable slug to a filename, so next year's permission slip
can replace this year's without breaking a link already printed on a flyer.

Documents are served through /documents/{slug} rather than from a static
mount, and NOT placed under /app/static, which is public forever. That is the
point: when member login exists it plugs into documents.visible() and no
public URL moves. The visibility field already carries 'members', which today
is hidden from the index and 404s rather than 403s, since a 403 would
advertise a document we cannot yet gate.
2026-08-30 09:02:29 -04:00
Claude 27f1a2104b calendar: consume the scout-calendar feed instead of local events.json
Events now come from EVENTS_FEED_URL (the scout-calendar container,
which serves Radicale mike/site73 as JSON). The last good copy is
cached to /data/events-cache.json and served whenever the feed is down
or empty; 'Nothing on the books' remains the cold-start floor only.
The round-trip test proved the feed reproduces all 32 rows of
app/events.json byte-identically, so nothing visible changes today.

Removes app/events.json, the first-boot seed copy, and the local load
path; README calendar section rewritten; compose gains EVENTS_FEED_URL
from the Portainer stack env.
2026-08-29 11:33:43 -04:00
claude f80243381e README: self-contained lead pipeline + decom notes 2026-08-24 13:54:53 -04:00
claude 1f9e214d29 port 8132 (8131 taken by triviapoc) 2026-08-24 13:17:59 -04:00
claude 83beebf35c scout-website: greenlanescouts73.org initial deploy (from scoutpoc redesign) 2026-08-24 13:15:13 -04:00